multi-entity stream profiles.
This commit is contained in:
@@ -105,6 +105,11 @@ Graylog event is not learned repeatedly. Related anomalies, profile deviations,
|
||||
and multi-stream correlations are grouped into investigation incidents with a
|
||||
compact evidence timeline.
|
||||
|
||||
Incident lifecycle state is stored locally in `state/signalscope-incidents.json`.
|
||||
Use the dashboard incident actions to acknowledge, resolve, or reopen an incident
|
||||
and attach a note. The state is keyed to a stable incident fingerprint so it can
|
||||
survive monitor refreshes even when the current detection window changes.
|
||||
|
||||
With a stream profile in place, SignalScope also builds independent burst
|
||||
baselines for authentication failures, DNS queries, and deny/block actions when
|
||||
those events are present. These are evaluated per configured entity, so a Windows
|
||||
|
||||
Reference in New Issue
Block a user